Alberto Fittarelli
banner
fittarelli.com
Alberto Fittarelli
@fittarelli.com
Sr. Researcher @citizenlab.ca, Disinformation & Harassment. Fmr. Meta. Trainer: find & expose covert influence. I like doers.
This entire keynote by @micahflee.com should be watched, but this excerpt, my friends - oh yes.

micahflee.com/practical-de...
October 26, 2025 at 4:21 PM
I thought we had agreed a few decades ago that Nazi propaganda was bad?
October 11, 2025 at 9:48 AM
15/ At the moment of publishing this, several PRISONBREAK profiles continue to be active. We notified X prior to publication - but got no reply.
October 3, 2025 at 3:32 AM
14/ So - who’s behind PRISONBREAK? We analytically weighed multiple hypotheses. The one most consistent with the available evidence is that the Israeli gov, directly or through a contractor, conducted the operation. Alternatively, but less likely, the US gov could be responsible for it.
October 3, 2025 at 3:32 AM
13/ Finally, we noticed PRISONBREAK consistently promoting and interacting with an account named “تل‌آویو تهران” (Tel Aviv Tehran), which used an AI-generated persona to spread content very similar to the IO’s one. Including another AI-made “Evin Prison” video.
October 3, 2025 at 3:32 AM
11/ We have many more examples in the report. But one that’s worth highlighting here is the creation of a whole videoclip for “Baraye”, an Iranian protest anthem. The catch? The lyrics were changed to a direct call for uprising; and the video is a (poorly made) deepfake of 3 known Iranian singers.
October 3, 2025 at 3:32 AM
10/ The use of AI in the campaign is *pervasive*. An attentive reader could have spotted the botched artifacts that often come with AI-generated videos, like the one claiming to show a crowd withdrawing their money from a bank in apparent panic. Just check the distorted human figure in yellow.
October 3, 2025 at 3:32 AM
9/ In fact, the network had only just started increasing pressure on the Iranian government by spreading claims of state bankruptcy, generalized lack of basic resources (water, for example), and broader societal unrest.
October 3, 2025 at 3:32 AM
8/ We now know that that didn’t happen. Iranian security forces retook control of the prison later that same day, temporarily transferring prisoners to different facilities before returning them to Evin in August 2025. But PRISONBREAK was not done yet.
October 3, 2025 at 3:32 AM
7/ What was possibly even more fascinating was the quick pivot by the network, immediately after the bombings stopped, to encourage Iranians in reaching the Evin Prison and free the prisoners. “The area is now safe”, some of the accounts posted.
October 3, 2025 at 3:32 AM
6/ The video initially tricked the international press into republishing it as real. Not only that: it was even reposted by the Israeli MoFA, Gideon Sa’ar. It was later spotted as AI-generated footage by several outlets.
October 3, 2025 at 3:32 AM
5/ Among the targeted locations, on June 23, was the infamous Evin Prison in Tehran, where political detainees routinely suffer torture and deprivation. And guess what? PRISONBREAK posted an AI-generated video of Evin’s bombing *while the bombing was still happening*.
October 3, 2025 at 3:32 AM
4/ As we know, in June 2025, tensions between Israel and Iran came to a head with the so-called “12-day War”, which saw targeted assassinations of key figures in the Iranian Islamic Republic, while the IDF bombed multiple Iranian locations.
October 3, 2025 at 3:32 AM
3/ We started analyzing the network’s behavior. Created in 2023, it only began posting regularly in January 2025. What could have been the purpose for this IO?
October 3, 2025 at 3:32 AM
2/ A few months ago, Darren Linvill @ the Media Forensics Hub at Clemson University made us aware of a set of X accounts that they were tracking. The profiles appeared to be inorganic: artificially set up to spread disparaging narratives on the Iranian regime. Also, they were clearly coordinated.
October 3, 2025 at 3:32 AM
I’m sure it’s not news to anyone actually paying attention, but we should probably care more that a lot of “name-surname-5digits” accounts are spreading the hashtag #abandonNATO on X at the moment.
September 17, 2025 at 12:28 PM
Allow me a breather after the two most stressful days of a stressful year so far.

Total lunar eclipse, 7 September.
September 10, 2025 at 8:27 PM
President Sergio Mattarella “speaking of a "new global corporatism" on the part of "new East India Companies" engaged in a project of colonial influence and exploitation, Mattarella spoke of a "neo-imperialist drive for domination, lethal for the future of humanity."
September 6, 2025 at 9:43 AM
You know what intelligence agencies were blinded by the terror of disappointing their political leadership to the point of contributing to the collapse of the nation?

The Soviet ones.
August 28, 2025 at 8:02 AM
Strong vibes.
August 16, 2025 at 3:01 PM
That @nytimes.com gives a platform to an obvious hack-and-leak influence operation was not what I was expecting to see today.
July 3, 2025 at 10:35 PM
8/ The bottom line: JUICYJAM lives on.

The Thai army and police’s response is contradictory and fully unsatisfactory.

Social media platforms allow the operation to continue unabated.

We @citizenlab.ca, like everyone else exposing this IO and its authors, became targets.
May 20, 2025 at 3:53 PM
7/ Kate used both Facebook’s and X’s reporting flows to flag the posts, and the related accounts/pages, for Bullying & Harassment.

Result? Report dismissed by Facebook. Resounding silence from X.
May 20, 2025 at 3:53 PM
6/ My colleague and co-author Katekanok (Kate) Wongsapakdee was next. For several weeks, up to this day, she was directly targeted by JUICYJAM. Among the information exposed was the fact that she had been an admin of the Free YOUTH group’s FB page - something she had kept very private to date.
May 20, 2025 at 3:53 PM
5/ Meanwhile, @prachatai.com - the first Thai paper reporting on JUICYJAM - and then we came under attack from the operation.

Here’s how it started, with Prachatai.
May 20, 2025 at 3:53 PM